
CCIE Security
Domain 4Objective 3
4.3 Cisco Devices for Administrative Access with Cisco ISE CCIE-SECURITY Practice Questions (Page 10)
Part of the 4.0 Identity Management, Information Exchange, and Access Control domain, which accounts for 25% of the CCIE-SECURITY exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~13–20 in this domain), expect 1–1 from this objective — we provide 53 practice questions to prepare you well beyond it. (estimate)
53questions here
11free pages
10concepts
25%of the exam
Questions 46–50
- 46
A small enterprise wants to use Cisco ISE to authenticate administrators accessing their network devices. They only need authentication (no per-command authorization) and want to minimize configuration complexity. They already use RADIUS for wireless authentication. Which approach is most appropriate?
Select an answer first - 47
An organization has multiple network device groups: core routers, access switches, and firewalls. They want to enforce different administrative policies: for example, only senior engineers can configure core routers, while junior staff can only view configurations on access switches. They plan to use Cisco ISE for device administration. What is the best way to implement this?
Select an answer first - 48
A security admin needs to ensure that network administrators can only execute 'show' commands and 'ping' on production devices, but they can execute any command on lab devices. They are using Cisco ISE for TACACS+ device administration. What should they configure?
Select an answer first - 49
A company wants to use Cisco ISE to authenticate administrators who connect via SSH to their Cisco routers. The routers are configured with 'aaa authentication login default group tacacs+'. The administrators use a variety of clients, some of which only support PAP. Which authentication protocol should be configured on ISE to ensure compatibility?
Select an answer first - 50
A security auditor requires evidence of who accessed network devices, what commands they executed, and when. The organization uses Cisco ISE for TACACS+ device administration. What must be enabled to meet this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “CCIE-SECURITY” is a trademark of its owner, used for identification only.